CVE-2020-2105UI Misrepresentation / Clickjacking in Project Jenkins

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 42.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 29
Latest updateMay 24

Description

REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

NVDjenkins/jenkins2.204.1+1
CVEListV5jenkins_project/jenkinsunspecified2.218+1

🔴Vulnerability Details

3
GHSA
Jenkins REST APIs vulnerable to clickjacking2022-05-24
OSV
Jenkins REST APIs vulnerable to clickjacking2022-05-24
CVEList
CVE-2020-2105: REST API endpoints in Jenkins 22020-01-29

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2020-01-292020-01-29
Red Hat
jenkins: REST APIs vulnerable to clickjacking2020-01-29

💬Community

2
Bugzilla
CVE-2020-2105 jenkins: REST APIs vulnerable to clickjacking2020-01-31
Bugzilla
CVE-2020-2105 jenkins: REST APIs vulnerable to clickjacking [fedora-all]2020-01-31
CVE-2020-2105 — UI Misrepresentation / Clickjacking | cvebase